Event-Driven Ansible Server Vulnerability Exposing API Access Controls
CVE-2026-12383
Key Information:
What is CVE-2026-12383?
A security flaw exists in the Event-Driven Ansible (EDA) server where the ExternalEventStreamViewSet has permissive access controls, allowing unrestricted access for unauthenticated requests. It relies solely on the Subject HTTP header value for mutual TLS (mTLS) authentication, failing to confirm the header's origin from a trusted proxy. This oversight enables an attacker to reach the EDA API endpoint using a spoofed Subject header, potentially injecting arbitrary events into mTLS-protected event streams. Furthermore, the expected certificate Distinguished Name is inadvertently exposed in the response body of 403 error messages, enhancing the risk of exploitation.
Affected Version(s)
Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:1.1.21-1.el8ap
Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:1.1.21-1.el9ap
Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:1.2.11-1.el9ap
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved